<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Connections</title>
	<atom:link href="http://breachblogsanjay.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://breachblogsanjay.wordpress.com</link>
	<description>Connections is a blog by Sanjay Mehta.</description>
	<lastBuildDate>Tue, 06 Oct 2009 17:00:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='breachblogsanjay.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/f207d83b401478eb500aea3640b0c254?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Connections</title>
		<link>http://breachblogsanjay.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://breachblogsanjay.wordpress.com/osd.xml" title="Connections" />
	<atom:link rel='hub' href='http://breachblogsanjay.wordpress.com/?pushpress=hub'/>
		<item>
		<title>WebDefend 4.0 &#8211; Protecting Your Organization&#8217;s Bottom Line</title>
		<link>http://breachblogsanjay.wordpress.com/2009/10/06/webdefend-4-0-protecting-your-organizations-bottom-line/</link>
		<comments>http://breachblogsanjay.wordpress.com/2009/10/06/webdefend-4-0-protecting-your-organizations-bottom-line/#comments</comments>
		<pubDate>Tue, 06 Oct 2009 16:59:18 +0000</pubDate>
		<dc:creator>breachblogsanjay</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://breachblogsanjay.wordpress.com/?p=122</guid>
		<description><![CDATA[Submitted by Sanjay Mehta 10/6/09 Breach today released the latest version of WebDefend, which features continuous web application performance monitoring, enhanced adaption and a new system-level dashboard. WebDefend 4.0’s new web application monitoring provides users with real-time visibility into the performance of their web applications. Now IT operators can track aggregate end user experience and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=breachblogsanjay.wordpress.com&amp;blog=5945345&amp;post=122&amp;subd=breachblogsanjay&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><em>Submitted by Sanjay Mehta 10/6/09</em></p>
<p>Breach today released the latest version of WebDefend, which features continuous web application performance monitoring, enhanced adaption and a new system-level dashboard.<br />
WebDefend 4.0’s new web application monitoring provides users with real-time visibility into the performance of their web applications. Now IT operators can track aggregate end user experience and report service levels by providing real-time visibility into areas such as site and URL level availability or site, URL and session level speed.</p>
<p>WebDefend 4.0 also tracks the top problem areas within a web application environment. As a result,  WebDefend’s application performance monitoring reduces the time necessary to identify and repair web application performance problems, reducing costs and increasing return on investment in web application environments. WebDefend 4.0 monitors every transaction in a web application environment, enabling accurate service level reporting and outsourcer management.</p>
<p>WebDefend 4.0 features several enhancements in the WebDefend Adaption engine, such as its ability to automatically relearn applications as they change in production – without manual intervention. The new enhancements help organizations use Adaption without negative security rules and signatures to eliminate false positives resulting from application changes, identify zero-day and targeted attacks, and block with confidence.</p>
<p>The appliance’s new system-level dashboard offers a real-time status of all systems in the WebDefend deployment. In short, WebDefend 4.0 accelerates the identification of application problems and trends that affect an organization’s bottom line.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/breachblogsanjay.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/breachblogsanjay.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/breachblogsanjay.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/breachblogsanjay.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/breachblogsanjay.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/breachblogsanjay.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/breachblogsanjay.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/breachblogsanjay.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/breachblogsanjay.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/breachblogsanjay.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/breachblogsanjay.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/breachblogsanjay.wordpress.com/122/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/breachblogsanjay.wordpress.com/122/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/breachblogsanjay.wordpress.com/122/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=breachblogsanjay.wordpress.com&amp;blog=5945345&amp;post=122&amp;subd=breachblogsanjay&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://breachblogsanjay.wordpress.com/2009/10/06/webdefend-4-0-protecting-your-organizations-bottom-line/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bf1fb93f553f9c00a95521f2c7148c02?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">Sanjay</media:title>
		</media:content>
	</item>
		<item>
		<title>Unlock the Power of Web Application Integrity</title>
		<link>http://breachblogsanjay.wordpress.com/2009/03/11/unlock-the-power-of-web-application-integrity/</link>
		<comments>http://breachblogsanjay.wordpress.com/2009/03/11/unlock-the-power-of-web-application-integrity/#comments</comments>
		<pubDate>Wed, 11 Mar 2009 17:42:29 +0000</pubDate>
		<dc:creator>breachblogsanjay</dc:creator>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://breachblogsanjay.wordpress.com/?p=92</guid>
		<description><![CDATA[Submitted by Sanjay Mehta 3/11/09 Web applications are the backbone of your businesses! But like all backbones, if you don’t take care of them they tend to become frail, poor performing, and vulnerable to injury over time. Unfortunately the difficulty in monitoring and maintaining the health and security of web applications isn’t as simple as [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=breachblogsanjay.wordpress.com&amp;blog=5945345&amp;post=92&amp;subd=breachblogsanjay&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><em>Submitted by Sanjay Mehta 3/11/09<img class="alignright size-thumbnail wp-image-95" title="key-30" src="http://breachblogsanjay.files.wordpress.com/2009/03/key-30.gif?w=128&#038;h=61" alt="key-30" width="128" height="61" align="right" /></em></p>
<p>Web applications are the backbone of your businesses! But like all backbones, if you don’t take care of them they tend to become frail, poor performing, and vulnerable to injury over time.</p>
<p>Unfortunately the difficulty in monitoring and maintaining the health and security of web applications isn’t as simple as a daily dose of calcium. The benefits associated with your web applications can quickly unravel if the integrity of the web applications becomes compromised. Defects in web applications can lead to: lost revenue and customers, damaged reputation and brand, code leakage, and compliance violations. This isn’t to say you should give up now – instead implement a focused program to identify possible defects and vulnerabilities that lie in your web applications and take steps to remediate.</p>
<p>Here are some “must do” steps to maintain the integrity and security of your web applications:</p>
<ul>
<li><strong>Stay current: </strong>Web applications and threats are continuously changing – you need a solution that is adaptive and is able to continuously monitor.</li>
<li><strong>Defense-in-depth, not just for networks anymore: </strong>Web applications need to be monitored through all steps in Development, QA, Staging, Production.</li>
<li><strong>The “response” matters: </strong>For a complete picture on the health of your web applications you need full outbound inspection and correlation.</li>
<li><strong>Compliance is a goal: </strong>Good security leads to compliance but compliance programs should not lead to better security.</li>
<li><strong>You cannot improve what you don’t understand: </strong>Foster an environment for application security and integrity by bridging the gap between your security and development teams.</li>
<li><strong>Find the right security partner!</strong></li>
</ul>
<p>Remember simple defects can result in serious problems.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/breachblogsanjay.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/breachblogsanjay.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/breachblogsanjay.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/breachblogsanjay.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/breachblogsanjay.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/breachblogsanjay.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/breachblogsanjay.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/breachblogsanjay.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/breachblogsanjay.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/breachblogsanjay.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/breachblogsanjay.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/breachblogsanjay.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/breachblogsanjay.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/breachblogsanjay.wordpress.com/92/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=breachblogsanjay.wordpress.com&amp;blog=5945345&amp;post=92&amp;subd=breachblogsanjay&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://breachblogsanjay.wordpress.com/2009/03/11/unlock-the-power-of-web-application-integrity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bf1fb93f553f9c00a95521f2c7148c02?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">Sanjay</media:title>
		</media:content>

		<media:content url="http://breachblogsanjay.files.wordpress.com/2009/03/key-30.gif?w=128" medium="image">
			<media:title type="html">key-30</media:title>
		</media:content>
	</item>
		<item>
		<title>Stuck in Groundhog Day Code Review</title>
		<link>http://breachblogsanjay.wordpress.com/2009/02/06/stuck-in-groundhog-day-code-review/</link>
		<comments>http://breachblogsanjay.wordpress.com/2009/02/06/stuck-in-groundhog-day-code-review/#comments</comments>
		<pubDate>Fri, 06 Feb 2009 17:11:51 +0000</pubDate>
		<dc:creator>breachblogsanjay</dc:creator>
				<category><![CDATA[Business & Security]]></category>

		<guid isPermaLink="false">http://breachblogsanjay.wordpress.com/?p=43</guid>
		<description><![CDATA[Submitted by Sanjay Mehta 2/5/2009 If you are like thousands of companies updated web applications on a regular basis, then you are probably investing a lot of time and money into performing continuous code reviews.  While your QA team is responsible for checking the quality and security of the new code, they are also stuck [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=breachblogsanjay.wordpress.com&amp;blog=5945345&amp;post=43&amp;subd=breachblogsanjay&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><em>Submitted by Sanjay Mehta 2/5/2009</em></p>
<p><img class="alignright" style="margin:2px 10px;" src="http://farm4.static.flickr.com/3099/3178289326_b7c94830b7_o.jpg" alt="GROUNDHOG 1" width="56" height="73" align="right" />If you are like thousands of companies updated web applications on a regular basis, then you are probably investing a lot of time and money into performing continuous code reviews.  While your QA team is responsible for checking the quality and security of the new code, they are also stuck with ensuring the new doesn’t break the old.  A nice, long, tedious process for sure&#8230;.fun stuff.  Add in a little pressure from the executive offices to get applications out on time and it’s no surprise that code sneaks out with application defects and security flaws.  And these “oversights” have major costs in remediation, not to mention the risks of alienating good customers, destroying brand, and exposing far too much information to users with malicious intent.  Let’s look at some numbers to make this more real:</p>
<p style="padding-left:30px;text-align:left;">- Every 1000 lines of code averages 15 security defects.<br />
- It takes 75 minutes on average to track down one defect.<br />
- Fixing each defect takes 2 to 9 hours.<br />
- The average business application has 150,000-250,000 lines of code.<br />
<strong>- Cost based on lowest figures from above: 9,000 x $25.00 =  $225,000.00</strong></p>
<p>Finding defects in code is a time consuming and expensive business process.  Automation and continuous inspection are key to getting a handle on this process.  I am not saying to toss your software development procedures out the window, but you should certainly consider alternatives and complementary strategies.  If you are looking for a starting point, check out <a href="http://www.breach.com/products/webdefend.html" target="_blank">Breach’s WebDefend</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/breachblogsanjay.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/breachblogsanjay.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/breachblogsanjay.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/breachblogsanjay.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/breachblogsanjay.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/breachblogsanjay.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/breachblogsanjay.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/breachblogsanjay.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/breachblogsanjay.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/breachblogsanjay.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/breachblogsanjay.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/breachblogsanjay.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/breachblogsanjay.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/breachblogsanjay.wordpress.com/43/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=breachblogsanjay.wordpress.com&amp;blog=5945345&amp;post=43&amp;subd=breachblogsanjay&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://breachblogsanjay.wordpress.com/2009/02/06/stuck-in-groundhog-day-code-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bf1fb93f553f9c00a95521f2c7148c02?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">Sanjay</media:title>
		</media:content>

		<media:content url="http://farm4.static.flickr.com/3099/3178289326_b7c94830b7_o.jpg" medium="image">
			<media:title type="html">GROUNDHOG 1</media:title>
		</media:content>
	</item>
		<item>
		<title>Announcing the Launch of WebDefend v3.5</title>
		<link>http://breachblogsanjay.wordpress.com/2009/01/30/announcing-the-launch-of-webdefend-v35/</link>
		<comments>http://breachblogsanjay.wordpress.com/2009/01/30/announcing-the-launch-of-webdefend-v35/#comments</comments>
		<pubDate>Fri, 30 Jan 2009 19:16:28 +0000</pubDate>
		<dc:creator>breachblogsanjay</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://breachblogsanjay.wordpress.com/?p=72</guid>
		<description><![CDATA[Submitted by Sanjay Mehta 1/30/09 We have liftoff.  I am happy to announce the release of Breach WebDefend v 3.5.    I have had the pleasure of working closely with our customers over the last 3 years as we have expanded WebDefend from a simple WAF into a comprehensive platform for application security, integrity and compliance.  [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=breachblogsanjay.wordpress.com&amp;blog=5945345&amp;post=72&amp;subd=breachblogsanjay&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><em>Submitted by Sanjay Mehta 1/30/09</em></p>
<p>We have liftoff.  I am happy to announce the release of Breach WebDefend v 3.5.    I have had the pleasure of working closely with <img class="alignright size-thumbnail wp-image-74" title="rocket-25" src="http://breachblogsanjay.files.wordpress.com/2009/01/rocket-25.jpg?w=63&#038;h=67" alt="rocket-25" width="63" height="67">our customers over the last 3 years as we have expanded WebDefend from a simple WAF into a comprehensive platform for application security, integrity and compliance.  Great products are certainly developed by great engineers, but they are defined by great prospects and customers.  With ideas from global leaders in finance, ecommerce, education, government and more, version 3.5 delivers increased performance, expanded blocking options, enhancements to scraping protection and much more.  So thanks to all that have standardized on WebDefend, we look forward to rolling out the new version.  And for those of you that haven’t joined the Breach Revolution&#8230;.jump on, it’s a great ride.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/breachblogsanjay.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/breachblogsanjay.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/breachblogsanjay.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/breachblogsanjay.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/breachblogsanjay.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/breachblogsanjay.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/breachblogsanjay.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/breachblogsanjay.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/breachblogsanjay.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/breachblogsanjay.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/breachblogsanjay.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/breachblogsanjay.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/breachblogsanjay.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/breachblogsanjay.wordpress.com/72/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=breachblogsanjay.wordpress.com&amp;blog=5945345&amp;post=72&amp;subd=breachblogsanjay&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://breachblogsanjay.wordpress.com/2009/01/30/announcing-the-launch-of-webdefend-v35/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bf1fb93f553f9c00a95521f2c7148c02?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">Sanjay</media:title>
		</media:content>

		<media:content url="http://breachblogsanjay.files.wordpress.com/2009/01/rocket-25.jpg?w=90" medium="image">
			<media:title type="html">rocket-25</media:title>
		</media:content>
	</item>
		<item>
		<title>Simplifying the Threat</title>
		<link>http://breachblogsanjay.wordpress.com/2009/01/13/59/</link>
		<comments>http://breachblogsanjay.wordpress.com/2009/01/13/59/#comments</comments>
		<pubDate>Tue, 13 Jan 2009 21:14:06 +0000</pubDate>
		<dc:creator>breachblogsanjay</dc:creator>
				<category><![CDATA[Industry News]]></category>

		<guid isPermaLink="false">http://breachblogsanjay.wordpress.com/2009/01/13/59/</guid>
		<description><![CDATA[Submitted by Sanjay Mehta 1/13/2009 Sometimes the simplest mistakes can cause great harm, and if you want proof, take a look at today’s web based business applications.  On January 12, 2009, CWE &#38; SANS announced the Top 25 Most Dangerous Programming Errors. This list assembled from more than 30 US and international security organizations will [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=breachblogsanjay.wordpress.com&amp;blog=5945345&amp;post=59&amp;subd=breachblogsanjay&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><em>Submitted by Sanjay Mehta 1/13/2009<img class="alignright size-thumbnail wp-image-58" title="simplify" src="http://breachblogsanjay.files.wordpress.com/2009/01/simplify.gif?w=68&#038;h=96" alt="simplify" width="68" height="96" align="right" /></em></p>
<p>Sometimes the simplest mistakes can cause great harm, and if you want proof, take a look at today’s web based business applications.  On January 12, 2009, CWE &amp; SANS announced the <a href="http://www.sans.org/top25errors/?utm_source=web&amp;utm_medium=text-ad&amp;utm_content=Announcement_Bar_20090111&amp;utm_campaign=Top25&amp;ref=37029" target="_blank">Top 25 Most Dangerous Programming Errors</a>. This list assembled from more than 30 US and international security organizations will revolutionize the way businesses maintain their web applications integrity and the way people are trained to write secure code.</p>
<p>This priority list helps all businesses, both large and small, take better control of their application security. Many enterprise corporations I visit have a hard time keeping up with the changes in a dynamic application environment, let along how those changes might introduce new security vulnerability or application integrity concerns.  But now, thanks to these industry experts, including Breach Security Labs leader Ryan Barnett, an understanding of the threat of security bugs, cyber espionage, and cyber crime has been simplified into a list of common programming errors. Thus, making it easier for developers to write code that will mitigate or eliminate the weakness in business applications.<br />
This project is another great step forward in creating a more secure Internet.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/breachblogsanjay.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/breachblogsanjay.wordpress.com/59/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/breachblogsanjay.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/breachblogsanjay.wordpress.com/59/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/breachblogsanjay.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/breachblogsanjay.wordpress.com/59/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/breachblogsanjay.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/breachblogsanjay.wordpress.com/59/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/breachblogsanjay.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/breachblogsanjay.wordpress.com/59/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/breachblogsanjay.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/breachblogsanjay.wordpress.com/59/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/breachblogsanjay.wordpress.com/59/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/breachblogsanjay.wordpress.com/59/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=breachblogsanjay.wordpress.com&amp;blog=5945345&amp;post=59&amp;subd=breachblogsanjay&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://breachblogsanjay.wordpress.com/2009/01/13/59/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bf1fb93f553f9c00a95521f2c7148c02?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">Sanjay</media:title>
		</media:content>

		<media:content url="http://breachblogsanjay.files.wordpress.com/2009/01/simplify.gif?w=68" medium="image">
			<media:title type="html">simplify</media:title>
		</media:content>
	</item>
		<item>
		<title>Minimizing Your Risk</title>
		<link>http://breachblogsanjay.wordpress.com/2009/01/05/minimizing-your-risk/</link>
		<comments>http://breachblogsanjay.wordpress.com/2009/01/05/minimizing-your-risk/#comments</comments>
		<pubDate>Mon, 05 Jan 2009 17:27:08 +0000</pubDate>
		<dc:creator>breachblogsanjay</dc:creator>
				<category><![CDATA[Business & Security]]></category>
		<category><![CDATA[Business Costs]]></category>
		<category><![CDATA[Web Application Security Attacks]]></category>

		<guid isPermaLink="false">http://breachblogsanjay.wordpress.com/?p=23</guid>
		<description><![CDATA[Submitted by Sanjay Mehta 1/6/2009 Would you jump out of a plane without a parachute?  This might be a silly question for most of you (except for the one or two crazy daredevils reading this blog), but I’m assuming most of you would not leap out of a plane to a most certain death.  I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=breachblogsanjay.wordpress.com&amp;blog=5945345&amp;post=23&amp;subd=breachblogsanjay&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><em>Submitted by Sanjay Mehta 1/6/2009<img class="size-full wp-image-36 alignright" title="sky-diving-cartoon" src="http://breachblogsanjay.files.wordpress.com/2009/01/sky-diving-cartoon.jpg?w=85&#038;h=85" alt="sky-diving-cartoon" width="85" height="85" align="right" /></em></p>
<p>Would you jump out of a plane without a parachute?  This might be a silly question for most of you (except for the one or two crazy daredevils reading this blog), but I’m assuming most of you would not leap out of a plane to a most certain death.  I believe that businesses that are deciding to leave their web applications unprotected will be facing the same type of risk, but instead of facing certain death they risk closing the doors to their business.</p>
<p>The amount of data leakage and data theft continues to soar (check out some of the latest web attacks at this website: <a href="http://www.breachblog.com" target="_blank">http://www.breachblog.com</a>) and the media has pounced on the chance to expose these attacks as they surface.  As a result, businesses must tighten up their defenses and web applications are a major hole in most security strategies.  Although most businesses realize the risk of not having well protected web applications many still wonder if it is worth the money to invest in web application security?  The short answer is yes!! But, just in case you don’t want to take just my word for it, I included a few statistics regarding the business costs associated with not protecting web applications.      </p>
<ul>
<li>In 2006, companies spent $5 million on average and up to $22 million to recover from corporate data loss.
<ul>
<li>Per capita cost of a data breach in 2006 was up 31% from 2005.</li>
<li>Cost of notification is $125/customer.</li>
</ul>
</li>
<li>25% of customers who receive notification will leave you, and another 20% are likely to leave (Potential result – 45% total customer loss).</li>
<li>Security breaches cost $90 to $305 per lost record.</li>
<li>Companies spend $180,000 on average after a breach to prevent further breaches.</li>
</ul>
<p>The relatively small investment of protecting a businesses’ web applications is trivial compared to the costs of leaving web applications unprotected. Businesses that do suffer a web attack not only suffer immediate monetary set backs, but their reputation and brand may be forever damaged.  The good thing is that the web application security industry continues to evolve and continues to produce new affordable solutions to keep you ahead of the hackers.  Please don’t jump out of any planes without parachutes and please don’t leave your web applications unprotected.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/breachblogsanjay.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/breachblogsanjay.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/breachblogsanjay.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/breachblogsanjay.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/breachblogsanjay.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/breachblogsanjay.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/breachblogsanjay.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/breachblogsanjay.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/breachblogsanjay.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/breachblogsanjay.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/breachblogsanjay.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/breachblogsanjay.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/breachblogsanjay.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/breachblogsanjay.wordpress.com/23/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=breachblogsanjay.wordpress.com&amp;blog=5945345&amp;post=23&amp;subd=breachblogsanjay&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://breachblogsanjay.wordpress.com/2009/01/05/minimizing-your-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bf1fb93f553f9c00a95521f2c7148c02?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">Sanjay</media:title>
		</media:content>

		<media:content url="http://breachblogsanjay.files.wordpress.com/2009/01/sky-diving-cartoon.jpg" medium="image">
			<media:title type="html">sky-diving-cartoon</media:title>
		</media:content>
	</item>
		<item>
		<title>Welcome to Connections!</title>
		<link>http://breachblogsanjay.wordpress.com/2008/12/29/welcome-to-connections/</link>
		<comments>http://breachblogsanjay.wordpress.com/2008/12/29/welcome-to-connections/#comments</comments>
		<pubDate>Mon, 29 Dec 2008 16:52:33 +0000</pubDate>
		<dc:creator>breachblogsanjay</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Industry trends]]></category>
		<category><![CDATA[Protect Web Applications]]></category>
		<category><![CDATA[Security Remediation]]></category>

		<guid isPermaLink="false">http://breachblogsanjay.wordpress.com/?p=4</guid>
		<description><![CDATA[Submitted by Sanjay Mehta 1/2/2009 Welcome to Connections!  My name is Sanjay Mehta, Executive Vice President of Breach Security.  Although I will be the principal writer for this blog I look forward to featuring posts from our clients, partners and colleagues.  For a little history on Breach, web application security, and even me&#8230;please check out our website at [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=breachblogsanjay.wordpress.com&amp;blog=5945345&amp;post=4&amp;subd=breachblogsanjay&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><em>Submitted by Sanjay Mehta 1/2/2009<img src="http://farm2.static.flickr.com/1082/3172093794_9a4a456071_t.jpg" border="0" alt="" width="90" height="100" align="right" /></em></p>
<p>Welcome to Connections!  My name is Sanjay Mehta, Executive Vice President of Breach Security.  Although I will be the principal writer for this blog I look forward to featuring posts from our clients, partners and colleagues.  For a little history on Breach, web application security, and even me&#8230;please check out our website at <a href="http://www.breach.com" target="_blank">www.breach.com</a>.</p>
<p>The web application security market is an exciting industry to be a part of and it has grown from a topic that nobody had heard of about 10 years ago &#8211; to being a primary focus for businesses striving to maintain their web application integrity.  These are a few of the principal reasons why people have become more educated and honed in on web application security:</p>
<ul>
<li>75% of all successful attacks occur at the application layer.</li>
<li>Web application provide a gateway to a corporations most sensitive confidential and customer information.</li>
<li>Network security solutions are not well suited to understand dynamic web applications.</li>
<li>Wide spread adoption  of encryption makes existing network security device ineffective for attack detection.</li>
<li>54% of security professionals admit that they have had to deal with a security incident.</li>
<li>44 States require companies to disclose data breaches.</li>
<li>80% of Americans are concerned about stolen identity. </li>
</ul>
<p>Having been on the forefront of this rapidly growing security industry for 10+ years, I decided to start this blog to help businesses quickly and easily connect to the latest web application security information.  On this blog you will find leading information on maintaining web application integrity, remediation techniques, business costs associated with web application attacks, advice on facilitating communication between departments, and much more…</p>
<p>I look forward to discussing these posts with you and I welcome any and all comments and feedback.  Thank you!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/breachblogsanjay.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/breachblogsanjay.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/breachblogsanjay.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/breachblogsanjay.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/breachblogsanjay.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/breachblogsanjay.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/breachblogsanjay.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/breachblogsanjay.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/breachblogsanjay.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/breachblogsanjay.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/breachblogsanjay.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/breachblogsanjay.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/breachblogsanjay.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/breachblogsanjay.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=breachblogsanjay.wordpress.com&amp;blog=5945345&amp;post=4&amp;subd=breachblogsanjay&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://breachblogsanjay.wordpress.com/2008/12/29/welcome-to-connections/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/bf1fb93f553f9c00a95521f2c7148c02?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">Sanjay</media:title>
		</media:content>

		<media:content url="http://farm2.static.flickr.com/1082/3172093794_9a4a456071_t.jpg" medium="image" />
	</item>
	</channel>
</rss>
